| Question | What the evidence supports |
|---|---|
| Are cyber-security incidents rising in Hong Kong? | Yes, if you use HKCERT’s recorded security-incident data: its 2026 outlook says incidents hit a record high and rose 27% year on year. |
| Is AI now a recognised cyber-risk category? | Yes. HKCERT’s 2026 outlook names AI-related attacks among top concerns, while its 2025 outlook lists AI content hijacking as a key emerging risk. |
| Has Hong Kong seen real deepfake fraud? | Yes. A Hong Kong finance worker was reportedly tricked into transferring more than US$25 million after fraudsters used deepfake technology to pose as colleagues on a video call; the AI Incident Database describes a Hong Kong case involving about HK$200 million. |
| Can we say official data proves AI scams rose by 1,000%? | Not from the public sources here. A media report citing Sumsub says Hong Kong deepfake incidents rose 1,000% in Q1 2024, but that is not the same as a complete official Hong Kong time series for AI-scam cases. |
HKCERT — the Hong Kong Computer Emergency Response Team Coordination Centre — is the key source for the clearest number. In its Hong Kong Cybersecurity Outlook 2026, HKCERT says security incidents in Hong Kong reached a record high, rising 27% year on year. The same release identifies AI-related attacks and supply-chain risks as top concerns, and says nearly 30% of enterprises lack dedicated cybersecurity personnel.
That 27% figure matters, but it has to be used carefully. It refers to overall security incidents, not a separate official count of AI scams. In other words, it is fair to say recorded cyber-security incidents are up; it is not fair to rewrite that number as ‘AI scams rose 27%’.
The previous year’s HKCERT outlook also pointed in the same direction. Its 2025 briefing said phishing had reached a five-year high, and highlighted supply-chain vulnerabilities and AI content hijacking as major emerging risks. The Hong Kong Police Force’s Cybersecurity Report 2024, produced by its Cyber Security and Technology Crime Bureau, covers the global and local cyber-security landscape, offers analysis and recommendations, and forecasts threats facing Hong Kong, reflecting continued official attention to defensive readiness.
The strongest Hong Kong example is the deepfake video-call fraud reported in 2024. CNBC reported that a Hong Kong finance worker was persuaded to transfer more than US$25 million after fraudsters used deepfake technology to disguise themselves as colleagues in a video call.
The AI Incident Database records a Hong Kong case in which attackers allegedly simulated a CFO and other video-conference participants, persuading an employee to transfer about HK$200 million, or roughly US$25 million.
The lesson is not just the size of the loss. It is the change in the trust model. Seeing a familiar face on a call, hearing a familiar voice, or receiving a convincing chat message can no longer be enough to approve a sensitive action, especially a high-value payment.
A FutureCIO article citing Sumsub data says Hong Kong saw a 1,000% increase in deepfake incidents in the first quarter of 2024. That is a useful warning sign, but it should not be treated as interchangeable with HKCERT or Hong Kong Police Force whole-market statistics.
The cautious reading is: commercial and media-reported data support the view that deepfake risk is escalating, while the public official evidence supports a broader rise in cyber-security incidents and heightened AI-related concern. What the available sources do not establish is an official, comparable, year-by-year percentage increase for AI-scam cases alone.
Do not approve large transfers on the strength of a video call, email or chat message alone. The Hong Kong deepfake case worked by making a fake video meeting appear credible. Use a separate channel — for example, a known phone number, an internal workflow, or a second authorised approver — before releasing money.
Make urgency a trigger for extra checks. Requests framed as confidential, time-critical, or coming from a senior executive should not bypass payment controls. Deepfake fraud is dangerous because it can turn a familiar face or voice into pressure; the safeguard should be a process, not a gut feeling.
Keep basic phishing defences sharp. AI may be the new headline, but phishing remains a central risk. HKCERT’s 2025 outlook said phishing had reached a five-year high, so staff training, URL checking, login-page scrutiny and cautious handling of attachments still matter.
Assign clear cybersecurity ownership. HKCERT’s 2026 outlook says nearly 30% of enterprises lack dedicated cybersecurity personnel. Even a small company should know who owns incident response, payment verification rules, supplier access reviews and escalation procedures.
Review suppliers and third-party access. HKCERT’s 2026 outlook names supply-chain risk as a top concern, and its 2025 outlook also flags supply-chain vulnerabilities as an emerging risk. Vendor accounts, shared logins, cloud permissions and outsourced systems should be reviewed regularly.
If the question is whether Hong Kong’s recorded cyber-security incidents have increased, the answer is yes: HKCERT says they hit a record high and rose 27% year on year.
If the question is exactly how much AI-scam cases have increased, the public evidence is less precise. AI-related attacks, AI content hijacking and deepfake video-call fraud are real and serious risks in Hong Kong, but a single official percentage increase for AI scams alone is not established by the sources available here.